ISO 17442-2:2020
(Main)Financial services - Legal entity identifier (LEI) - Part 2: Application in digital certificates
Financial services - Legal entity identifier (LEI) - Part 2: Application in digital certificates
This document specifies a standardised way of embedding the legal entity identifier (LEI) code, as represented in ISO 17442-1, in digital certificates, represented by the International Telecommunications Union (ITU) Recommendation X.509 and its ISO equivalent standard, ISO/IEC 9594-8. This document specifies the structure of a public key certificate conforming with ISO/IEC 9594-8 in which the LEI is embedded.
Services financiers — Schéma d'identifiant d'entité légale (IEL) — Partie 2: Utilisation dans les certificats numériques
General Information
- Status
- Published
- Publication Date
- 17-Aug-2020
- Technical Committee
- ISO/TC 68/SC 8 - Reference data for financial services
- Drafting Committee
- ISO/TC 68/SC 8 - Reference data for financial services
- Current Stage
- 9060 - Close of review
- Completion Date
- 04-Mar-2031
Relations
- Effective Date
- 23-Apr-2020
Overview
ISO 17442-2:2020 is an international standard developed by the International Organization for Standardization (ISO) that specifies a standardized method to embed the Legal Entity Identifier (LEI) into digital certificates. The LEI, defined in ISO 17442-1, provides a unique and persistent identifier for legal entities engaged in financial transactions worldwide. This standard integrates LEI with the digital certificate framework based on ITU Recommendation X.509 and ISO/IEC 9594-8, enabling enhanced identity management for financial services and beyond.
By embedding the LEI into X.509 public key certificates, ISO 17442-2:2020 facilitates unique entity identification combined with authentication, improving trust and operational efficiency in electronic transactions.
Key Topics
- LEI Integration in Digital Certificates: Specifies the structure for embedding LEI codes within the extensions of X.509 digital certificates using Object Identifiers (OID).
- Object Identifier (OID) Usage: Defines OID
1.3.6.1.4.1.52266.1for embedding LEI and1.3.6.1.4.1.52266.2for optionally encoding roles of individuals within organizations. - Public Key Certificate Structure: Aligns with ISO/IEC 9594-8, ensuring compatibility with existing digital certificate frameworks used globally.
- Role-Based Identification: Supports inclusion of individual roles (e.g., CEO) associated with the LEI in the digital certificate to further enhance identity clarity.
- Mutual Benefits: Combines the uniqueness and persistence of LEIs with the authentication strength of digital certificates to improve identity validation and reduce reliance on repeated certificate revocation when entity data changes.
Applications
- Financial Services: Streamlines regulatory compliance, "know your customer" (KYC) procedures, and risk management by embedding verifiable LEI information in digital certificates.
- Secure Digital Identity Management: Enhances secure online business interactions, digital signing, and encrypted communication by providing both entity identity (via LEI) and owner authentication (via certificates).
- Certificate Lifecycle Efficiency: Reduces administrative overhead by separating entity reference data maintenance from the certificate renewal process, as LEI data updates do not require certificate revocation.
- Cross-Organization Authentication: Facilitates trusted interaction between entities by ensuring digital certificates reference a unique, universally recognized identifier, supporting straight-through processing (STP) in transactions.
- IT and Cybersecurity: Supports service providers and certificate authorities in creating standardized, interoperable digital certificates that include essential legal entity data with role information for identity verification.
Related Standards
- ISO 17442-1:2020 - Legal Entity Identifier (LEI) Assignment: Provides foundational guidelines for assigning LEIs to organizations.
- ISO/IEC 9594-8:2017 - Directory: Public-key and Attribute Certificate Frameworks: Defines the structure and protocols for X.509 public key certificates used in this standard.
- ITU Recommendation X.509: International framework for public key certificates used in securing digital identities.
- ISO/IEC 9834-1:2012 - Object Identifier Registration Procedures: Covers the administration of OIDs employed for encoding LEIs in certificates.
Summary
ISO 17442-2:2020 establishes a robust, interoperable method for embedding Legal Entity Identifiers in digital certificates, bridging persistent entity identification with cryptographic identity assurance. This integration fosters greater trust, efficiency, and security across financial and digital transactions worldwide. By leveraging this standard, organizations, certificate authorities, and technology providers can enhance digital identity management, reduce duplication and errors, and support a more streamlined and secure global financial ecosystem.
Keywords: ISO 17442-2, Legal Entity Identifier, LEI, digital certificates, X.509, ISO/IEC 9594-8, financial services, identity management, public key certificate, object identifier, digital identity, certificate extensions, authentication, KYC compliance, secure transactions.
Frequently Asked Questions
ISO 17442-2:2020 is a standard published by the International Organization for Standardization (ISO). Its full title is "Financial services - Legal entity identifier (LEI) - Part 2: Application in digital certificates". This standard covers: This document specifies a standardised way of embedding the legal entity identifier (LEI) code, as represented in ISO 17442-1, in digital certificates, represented by the International Telecommunications Union (ITU) Recommendation X.509 and its ISO equivalent standard, ISO/IEC 9594-8. This document specifies the structure of a public key certificate conforming with ISO/IEC 9594-8 in which the LEI is embedded.
This document specifies a standardised way of embedding the legal entity identifier (LEI) code, as represented in ISO 17442-1, in digital certificates, represented by the International Telecommunications Union (ITU) Recommendation X.509 and its ISO equivalent standard, ISO/IEC 9594-8. This document specifies the structure of a public key certificate conforming with ISO/IEC 9594-8 in which the LEI is embedded.
ISO 17442-2:2020 is classified under the following ICS (International Classification for Standards) categories: 03.060 - Finances. Banking. Monetary systems. Insurance. The ICS classification helps identify the subject area and facilitates finding related standards.
ISO 17442-2:2020 has the following relationships with other standards: It is inter standard links to ISO 17442:2019. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.
ISO 17442-2:2020 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
INTERNATIONAL ISO
STANDARD 17442-2
First edition
2020-08
Financial services — Legal entity
identifier (LEI) —
Part 2:
Application in digital certificates
Services financiers — Schéma d'identifiant d'entité légale (IEL) —
Partie 2: Utilisation dans les certificats numériques
Reference number
©
ISO 2020
© ISO 2020
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting
on the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address
below or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii © ISO 2020 – All rights reserved
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Structure of the X.509 public key certificate with embedded LEI .1
Annex A (informative) Example digital certificate with embedded LEI and role .3
Annex B (informative) Mutual benefits of combining LEIs and digital certificates for
identity management . 4
Bibliography . 5
Foreword
ISO (the International Organization for Standardization) is a worldwide federation of national standards
bodies (ISO member bodies). The work of preparing International Standards is normally carried out
through ISO technical committees. Each member body interested in a subject for which a technical
committee has been established has the right to be represented on that committee. International
organizations, governmental and non-governmental, in liaison with ISO, also take part in the work.
ISO collaborates closely with the International Electrotechnical Commission (IEC) on all matters of
electrotechnical standardization.
The procedures used to develop this document and those intended for its further maintenance are
described in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the
different types of ISO documents should be noted. This document was drafted in accordance with the
editorial rules of the ISO/IEC Directives, Part 2 (see www .iso .org/ directives).
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. ISO shall not be held responsible for identifying any or all such patent rights. Details of
any patent rights identified during the development of the document will be in the Introduction and/or
on the ISO list of patent declarations received (see www .iso .org/ patents).
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and
expressions related to conformity assessment, as well as information about ISO's adherence to the
World Trade Organization (WTO) principles in the Technical Barriers to Trade (TBT), see www .iso .org/
iso/ foreword .html.
This document was prepared by Technical Committee ISO/TC 68, Financial services, Subcommittee SC
8, Reference data for financial services.
This first edition of ISO 17442-2, along with ISO 17442-1, cancels and replaces ISO 17442:2019, which
has been technically revised.
A list of all parts in the ISO 17442 series can be found on the ISO website.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www .iso .org/ members .html.
iv © ISO 2020 – All rights reserved
Introduction
Legal entity identification is an integrated and necessary component of financial transactions. Entering
into business relationships requires “know your customer” processes to be initiated and maintained for
the duration of these relationships and any longer-term data retention requirements to be addressed.
Parties involved in financial transactions need to be identified in the records of these transactions.
Then the risk for each party and the resulting concentration risk need to be measured. All of this needs
to be achieved while the support for straight through processing (STP) is maintained.
Both legal entity identifiers (LEIs) and digital certificates are established tools for identity management.
These tools can be of even greater benefit to users if they are combined so that they complement each
other, providing a new solution to standardized digital identity. Annex B outlines the mutual benefits of
this combination.
It is possible, for example, to display the LEI in a web browser address bar from the digital certificate or
retrieve information from the LEI data record using an application programming interface (API).
Furthermore, the public key certificate can be linked to the LEI and its associated data record.
INTERNATIONAL STANDARD ISO 17442-2:2020(E)
Financial services — Legal entity identifier (LEI) —
Part 2:
Application in digital certificates
1 Scope
This document specifies a standardised way of embedding the legal entity identifier (LEI) code, as
represented in ISO 17442-1, in digital certificates, represented by the International Telecommunications
Union (ITU) Recommendation X.509 and its ISO equivalent standard, ISO/IEC 9594-8.
This document specifies the structure of a public key certificate conforming with ISO/IEC 9594-8 in
which the LEI is embedded.
2 Normative references
There are no normative references in this document.
3 Terms and definitions
For the purposes of this document, the following terms and definitions apply.
ISO and IEC maintain terminological databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at http
...










Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.
Loading comments...